Apple Mac Os X Server vulnerabilities
654 known vulnerabilities affecting apple/mac_os_x_server.
Total CVEs
654
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL75HIGH157MEDIUM363LOW59
Vulnerabilities
Page 26 of 33
CVE-2006-3503P4MEDIUMCVSS 5.1v10.4.72006-08-03
CVE-2006-3503 [MEDIUM] CVE-2006-3503: Integer overflow in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denia
Integer overflow in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed GIF image.
nvd
CVE-2006-3501P4MEDIUMCVSS 5.1v10.4.72006-08-03
CVE-2006-3501 [MEDIUM] CVE-2006-3501: Integer overflow in ImageIO for Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a deni
Integer overflow in ImageIO for Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Radiance image.
nvd
CVE-2008-1579P4MEDIUMCVSS 5.0v10.4.11v10.5+2 more2008-06-02
CVE-2008-1579 [MEDIUM] CWE-200 CVE-2008-1579: Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive informa
Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message produced upon access to a nonexistent blog.
nvd
CVE-2005-1043P4MEDIUMCVSS 5.0v10.3.9v10.4+1 more2005-04-14
CVE-2005-1043 [MEDIUM] CVE-2005-1043: exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption
exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.
nvd
CVE-2008-0999P4HIGHCVSS 7.1v10.5.22008-03-18
CVE-2008-0999 [HIGH] CWE-20 CVE-2008-0999: Apple Mac OS X 10.5.2 allows user-assisted attackers to cause a denial of service (crash) via a craf
Apple Mac OS X 10.5.2 allows user-assisted attackers to cause a denial of service (crash) via a crafted Universal Disc Format (UDF) disk image, which triggers a NULL pointer dereference.
nvd
CVE-2004-1832P4MEDIUMCVSS 5.0v10.32004-12-31
CVE-2004-1832 [MEDIUM] CVE-2004-1832: Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a
Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large amount of data to TCP port 660.
nvd
CVE-2006-3504P4MEDIUMCVSS 5.1v10.4.72006-08-03
CVE-2006-3504 [MEDIUM] CVE-2006-3504: The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "sa
The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.
nvd
CVE-2009-0141P4MEDIUMCVSS 5.5v10.4.11v10.5.62009-02-13
CVE-2009-0141 [MEDIUM] CWE-732 CVE-2009-0141: XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure w
XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.
nvd
CVE-2007-2404P4MEDIUMCVSS 5.0v10.3v10.3.1+19 more2007-08-03
CVE-2007-2404 [MEDIUM] CVE-2007-2404: CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allow
CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.
nvd
CVE-2010-0541P4MEDIUMCVSS 4.3v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-0541 [MEDIUM] CWE-79 CVE-2010-0541: Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in Ruby in Apple Mac OS X 10.5.8
Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in Ruby in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote attackers to inject arbitrary web script or HTML via a crafted URI that triggers a UTF-7 error page.
nvd
CVE-2011-3220P4MEDIUMCVSS 4.3≤ 10.7.1v10.0+66 more2011-10-14
CVE-2011-3220 [MEDIUM] CWE-200 CVE-2011-3220: QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files
QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.
nvd
CVE-2009-2840P4MEDIUMCVSS 4.9v10.5.82009-11-10
CVE-2009-2840 [MEDIUM] CVE-2009-2840: Spotlight in Apple Mac OS X 10.5.8 does not properly handle temporary files, which allows local user
Spotlight in Apple Mac OS X 10.5.8 does not properly handle temporary files, which allows local users to overwrite arbitrary files in the context of a different user's privileges via unspecified vectors.
nvd
CVE-2010-1803P4MEDIUMCVSS 4.3v10.6.0v10.6.1+3 more2010-11-15
CVE-2010-1803 [MEDIUM] CVE-2010-1803: Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its rem
Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its remote AFP volume, which allows remote attackers to obtain sensitive information by spoofing this volume.
nvd
CVE-2004-0514P4HIGHCVSS 7.2v10.3v10.3.1+2 more2004-08-18
CVE-2004-0514 [HIGH] CVE-2004-0514: Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."
nvd
CVE-2007-4694P4MEDIUMCVSS 4.3v10.4.1v10.4.2+8 more2007-11-15
CVE-2007-4694 [MEDIUM] CWE-264 CVE-2007-4694: Safari in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to access local content via fi
Safari in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to access local content via file:// URLs.
nvd
CVE-2010-3796P4MEDIUMCVSS 4.3v10.5.8v10.6.0+4 more2010-11-16
CVE-2010-3796 [MEDIUM] CWE-200 CVE-2010-3796: Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS f
Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DOM modifications.
nvd
CVE-2006-1220P4MEDIUMCVSS 4.6v10.0v10.1+30 more2006-03-14
CVE-2006-1220 [MEDIUM] CVE-2006-1220: Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to
Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to execute arbitrary code via unknown attack vectors related to a large message header size, which leads to a heap-based buffer overflow.
nvd
CVE-2010-0502P4MEDIUMCVSS 4.3≤ 10.6.2v10.5+11 more2010-03-30
CVE-2010-0502 [MEDIUM] CVE-2010-0502: iChat Server in Apple Mac OS X Server before 10.6.3, when group chat is used, does not perform loggi
iChat Server in Apple Mac OS X Server before 10.6.3, when group chat is used, does not perform logging for all types of messages, which might allow remote attackers to avoid message auditing via an unspecified selection of message type.
nvd
CVE-2006-1552P4MEDIUMCVSS 5.0v10.4v10.4.1+4 more2006-03-31
CVE-2006-1552 [MEDIUM] CWE-189 CVE-2006-1552: Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a d
Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".
nvd
CVE-2010-1381P4LOWCVSS 3.5v10.5.8v10.6.0+3 more2010-06-17
CVE-2010-1381 [LOW] CVE-2010-1381: The default configuration of SMB File Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, enabl
The default configuration of SMB File Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, enables support for wide links, which allows remote authenticated users to access arbitrary files via vectors involving symbolic links. NOTE: this might overlap CVE-2010-0926.
nvd